An Architecture of Network Intrusion Detection and Prevention Systems for More Seamless Deployments

Shotaro Usuzaki, Ryo Saito · 2024

Network intrusion detection and prevention systems (NIDPS) are vital in defending against malicious network traffic. However, NIDPS has drawbacks in inspecting the traffic. While our previous paper addressed the issue by real-time switching the traffic path to direct the traffic to NIDPS with ARP spoofing, this approach resulted in unreliable traffic capturing for inspecting it. Therefore, we propose a new NIDS deployment mechanism based on the client-server model instead of using the ARP protocol. In this architecture, the monitored hosts (clients) request NIDPS controllers (servers) to modify the ARP entry to direct the traffic path to NIDPS. We verified the proposed method's performance in a virtual network environment through an evaluation experiment and showed that it could switch traffic in real time, just like the ARP Spoofing-based method.

Read the paper · More papers on PaperTik